Skip to content

Information Notice: Privacy, Access to Information Notice for Case Individuals


INFORMATION NOTICE STATEMENT

This notice describes how Rainbow Railroad collects, uses, discloses, and retains personal information. “Personal information” means information about an identifiable individual.

To do our work, Rainbow Railroad needs to collect and store personal and/or organizational information. We take very seriously protecting the personal and organizational information that we collect and store when we provide services. 

We are committed to taking all reasonable steps to ensure that information we collect,  is provided to us consensually, and that it is kept safe and, shared only when requested or as part of agreements ensuring informed consent, and that our standard of data privacy, data protection and access to information are consistent with those of the relevant legislation in Ontario, Canada & the United States, and of the European General Data Protection Regulation (GDPR)—currently the global gold standard.

We share a person or an organization’s information only when requested or consented to by that individual or organization, or in limited exceptional circumstances if required to do so by the laws of Ontario, Canada, or the United States, or in an emergency if we need to protect a person’s safety and if not disclosing that information might lead to bodily harm or death.

This Privacy and Access to Information notice relates to our use of:

  • Any personal or organizational information we collect when providing services; and

This information notice explains the following:

  • What personal information Rainbow Railroad may collect;
  • How Rainbow Railroad will use the personal information we collect;
  • When Rainbow Railroad may use a person’s details to contact them—and the options available to our stakeholders regarding the information we collect and keep, and regarding our contacting them; and;
  • Whether Rainbow Railroad will disclose a person’s personal or organizational details to anyone else;
  • Our choices regarding the personal and organizational information they provide to us;

DEFINITIONS

Personal information: Information that identifies a person, their contact information and any other information about them as disclosed in order to either receive Rainbow Railroad services; 

Referring Partner: An organization or government with which Rainbow Railroad has a negotiated agreement to jointly support the relocation of refugees. In such agreements Rainbow Railroad either receives referrals of refugees from a Referring Partner and/ or refers individuals to a Referring Partner.

APPLIES TO

  • People who apply for help and/or receive help from Rainbow Railroad

LEGISLATIVE COMPLIANCE & GUIDANCE

Rainbow Railroad maintains offices in Ontario, Canada and New York, USA, but engages with individuals globally. 

Rainbow Railroad meets or exceeds the information collection, storage, data retention and sharing standards required under Ontario, Canada, the United States, and the European Union.

With respect to the collection, storage, sharing or retention of personal information, the following legislation either may mandate compliance or in other cases provide standards or guidance which Rainbow Railroad follows. 

Legislation or Regulation

In Canada:

  • Ontario’s Freedom of Information and Protection of Privacy Act, 1990
  • The Personal Information Protection and Electronic Documents Act (PIPEDA)scope: fund development
  • Federal Income Tax Act, Employment Insurance Act, and Canada Pension Plan & Ontario income tax, sales tax and employer health (payroll) tax statutes—scope: Canadian employee information

In the United States

  • The U.S. Privacy Act
  • The U.S. Freedom of Information Act
  • US Equal Opportunity Employment Commission Regulationscope: US employee information
  • Other state legislation where Rainbow Railroad fundraises—scope: donor information

In Europe

  • The General Data Protection Regulation (GDPR)

In addition to legislative or regulatory authority, Rainbow Railroad seeks to align its practices with those advocated by or adopted by:

  • the Office of the Privacy Commissioner of Canada
  • the Information and Privacy Commissioner of Ontario
  • the Office of the United Nations High Commissioner for Refugees, specifically the practices in the personal data protection and privacy framework established by the General Policy on the Protection of Personal Data and Privacy (2022).

INFORMED CONSENT

This Privacy, Access to Information notice (as regularly updated) is posted publicly, making it readily available to any person or individual before they become a service user.

By using our website(s)/ Request for help forms a person is indicating that they consent to our use of their personal information as described in this Information Notice (as regularly updated).

If and when a person becomes a service user, they are indicating that they consent to the use of their personal information as described in this notice, and may exercise choices as per this notice.

In the area of Rainbow Railroad’s delivery of services to potential and current refugees, when an individual requests Rainbow Railroad’s services, Rainbow Railroad points those individuals to this notice regarding the treatment of their personal information, explains this information notice as necessary and answers any questions.

DATA COLLECTION & USE OF COLLECTED DATA

When a person accesses any of Rainbow Railroad’s services, they are ‘opting in’ to our collecting personal information about them. 

This information can consist of data points as submitted by a person with our online services (e.g. on our websites), such as (but not limited to) their name, email address, address, location and sometimes organisation. 

Rainbow Railroad only collects sensitive data such as sexual orientation or gender identity or other health data of individuals as necessary, in the context of:

  • Managing our service to determine eligibility to receive support as an LGBTQIA+ person.

Rainbow Railroad might also use Google Analytics to collect data about a person’s device and about their visits to and use of this website (these are data about a browser, a general location as determined from an IP address and provided by a browser, the site from which a person comes, and the links followed when leaving the site).

Rainbow Railroad might also use personal data for statistical and analytical purposes in order to administer the website, improve our services, or, on aggregated non-identifiable basis, provide reports to donors and funders, or for advocacy purposes. Any identifiable information in Rainbow Railroad materials will be done with express written consent.

CONSENT TO BE CONTACTED

Rainbow Railroad may contact a person:

  1. in relation to any service request or ongoing service provision;
  2. In relation to any correspondence we receive from a person;
  3. for information purposes, where we believe a person has consented for us to do so. If a person receives anything from Rainbow Railroad they have not requested, they may let us know. Generally, Rainbow Railroad will only use a person’s personal information within the organisation. However, sometimes Rainbow Railroad uses third party services to:
    • Process personal information (such as a person’s email address and subscription preferences);
    • To deliver any other services they have requested from us. 

Rainbow Railroad requires these third parties to comply strictly with our instructions and we require that these third parties do not use personal information for their own business purposes.

People who subscribe to receive information from Rainbow Railroad are implicitly ‘opting in’/ consenting to be contacted to receive that information, and may opt out at any time.

DATA PROTECTION & LIMITED REASONS FOR DISCLOSING INFORMATION

Rainbow Railroad has implemented strict cyber-security measures to protect personal information that we collect. 

Rainbow Railroad never shares personal information with third parties beyond: 

  • Third parties performing services on our behalf or who are referring partners with Rainbow Railroad in refugee resettlement, and then only with strict privacy and confidentiality agreements with those third parties to ensure that there has been informed consent of the individual(s) in question and that both parties are acting in the vital and best interest of the refugee; and/or
  • For legal obligations: When we need to comply with a legal or regulatory obligation; and/or
  • For ethical reasons, specifically: In an emergency, if we need to protect a person’s safety and if failure to disclose that information might lead to an individual’s bodily harm or death.

We do not sell, trade, rent or otherwise share for marketing purposes personal information with third parties without a person’s consent except as stated above.

DATA RETENTION & DELETION

Rainbow Railroad stores personal and organizational information for as long as we deem it necessary to provide services as per a person or an organization’s request, and to comply with local legislation. This is in relation to the personal data provided when contacting us and/or seeking support from us. 

A person has the right to access the personal or organizational data that we store about them. They can contact us at any time  by emailing their caseworker or our privacy officer at info@rainbowrailroad.org to request their data be modified or deleted, and Rainbow Railroad will do so within a reasonable amount of time.

For individuals who apply for help and/or receive help from Rainbow Railroad, Rainbow Railroad’s standard is to keep information about those individuals indefinitely—unless requested or required to delete the information. This is done in order to more easily provide follow-up service to those individuals if applicable, for internal program improvement audits or to contact individuals for consent to participate in research, program evaluations and collective advocacy and movement building.

Exceptions are made where Rainbow Railroad has negotiated a different arrangement with a Referring Partner in order to meet a standard of that referring partner and/or an informed consent agreement that the Referring Partner made with the individual(s) whose information is being transferred to or from Rainbow Railroad. 

Notwithstanding any agreement with a Referring Partner or Rainbow Railroad’s standard practice, if an individual requests that their information be deleted or destroyed, Rainbow Railroad will comply with that request within five business days unless one of the following apply, in which case the deletion will occur as soon as possible after the following no longer apply:

  • If there is a legitimate basis for the processing of the information; OR
  • Where the personal data is still necessary for the purposes for which it was collected; OR
  • If the information has legal value; OR
  • If the information is required for accountability of Rainbow Railroad’s actions; OR
  • If the information is still required for Rainbow Railroad to support another individual.

CHOICES REGARDING PERSONAL OR ORGANIZATIONAL INFORMATION COLLECTED BY RAINBOW RAILROAD

Please contact your caseworker or help@rainbowrailroad.org to:

  • Access, review, correct, update or have personal information deleted from our records—and we will comply if permitted by local legislation;
  • Access, review, correct, update or have organizational information deleted from our records;
  • Ask any questions or express concerns regarding our collection, use and sharing of personal or organizational information;
  • Request that we transfer a person’s personal information  that we have collected to another organization or directly to the person.

Once a person’s identity is confirmed, we will deal with the request as soon as reasonably practicable. 

People accessing this information notice on our website, and who wish to unsubscribe to receiving information/services from us may email info@rainbowrailroad.org.

NOTIFICATION IN CASE OF DATA BREACH

Rainbow Railroad will notify individuals as soon as possible if their information may have been subject to a personal data breach. We will inform those individuals of the measures we have or will be implementing to mitigate the harm where such a personal data breach is likely to result in high risks to their security, rights and freedoms.

USE OF COOKIES ON WEBSITES

The Rainbow Railroad website uses cookies. These cookies are essential to the effective operation of our website. Cookies make the interaction between a person and the website faster and easier. 

Most notably we use Google Analytics, a web analytics service which uses ‘cookies’. This service sets its own cookies. Google uses this information for tracking how a person uses the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage.

LIMITATIONS

As part of Rainbow Railroad’s services, our website may provide links to other websites or applications, and/or our employees or volunteers may provide information about other services. However, we are not responsible for the privacy practices employed by those websites or the information or content they contain, nor are we responsible for the privacy practices of the organizations about which we provide information.

CHANGES TO THIS NOTICE

We may update this Privacy, Access to Information Notice from time to time to reflect changes in the law and/or our privacy practices.

For non-material changes or clarifications, there be no notice other than an updating of the notice on our website, and these will take effect immediately.

For any significant changes to this notice, we will contact our stakeholders’ primary email address or place a prominent notice on our website. Significant changes will go into effect 30 days following such notification.

We will always update the date of the latest revision of our Privacy, Access to Information Notice at the top of the privacy webpage.

We encourage website users to check whether we have recently made any changes to our Privacy, Access to Information and Notice.

Our Privacy Officer can be reached at: ■ privacy@rainbowrailroad.org